โ† All cheat sheets

SPIDERFOOT

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Open-source OSINT automation tool that queries 200+ data sources
to build intelligence on targets (IPs, domains, emails, names, etc.).

INSTALLATION#

# pip
pip install spiderfoot

# From source
git clone https://github.com/smicallef/spiderfoot
cd spiderfoot
pip install -r requirements.txt

# Docker
docker pull spiderfoot/spiderfoot
docker run -p 5001:5001 spiderfoot/spiderfoot

# Kali Linux
sudo apt install spiderfoot

STARTING SPIDERFOOT#

# Web UI (recommended)
python3 sf.py -l 127.0.0.1:5001

# Access at: http://127.0.0.1:5001

# CLI mode (headless)
python3 sfcli.py

# With custom config
python3 sf.py -l 0.0.0.0:5001 -d /path/to/spiderfoot.db

WEB UI WORKFLOW#

1. New Scan: click "New Scan"
2. Enter target (domain, IP, email, name, etc.)
3. Select scan type:
   - All: every module (slow, comprehensive)
   - Footprint: passive recon
   - Investigate: deeper analysis
   - Passive: no direct target contact
   - Custom: pick specific modules
4. Start scan
5. Browse results in tabs (Data, Graph, Status)

SCAN TYPES#

# Footprint (passive reconnaissance)
  - DNS, WHOIS, certificate transparency
  - Web scraping, social media
  - No active probing of target

# Investigate (moderate depth)
  - Footprint + some active checks
  - Port scanning, web crawling
  - Banner grabbing

# Passive (zero target contact)
  - Only queries third-party sources
  - No packets sent to target
  - Safe for initial recon

# All (comprehensive)
  - Every available module
  - Active + passive techniques
  - Longest scan time

TARGET TYPES#

  - Domain name:       example.com
  - IP address:        1.2.3.4
  - IP subnet:         10.0.0.0/24
  - Email address:     user@example.com
  - Phone number:      +1234567890
  - Person name:       "John Smith"
  - Username:          jsmith
  - Bitcoin address:   1A1zP1eP5QGefi2DMPTfTL5SLmv7DivfNa
  - ASN:               AS15169

CLI MODE#

# Run scan from command line
python3 sfcli.py -s target.com -t all

# Specific modules
python3 sfcli.py -s target.com -m sfp_dns,sfp_whois,sfp_shodan

# Output formats
python3 sfcli.py -s target.com -t passive -o json > results.json
python3 sfcli.py -s target.com -t passive -o csv > results.csv

# Quiet mode
python3 sfcli.py -s target.com -t passive -q

KEY MODULES (200+ AVAILABLE)#

# DNS & Domain
sfp_dns                  # DNS resolution and records
sfp_dnsbrute             # DNS subdomain brute force
sfp_dnsresolve           # DNS resolution
sfp_dnsdumpster          # DNSDumpster lookup
sfp_dnszonexfer          # DNS zone transfer attempt
sfp_subdomain            # Subdomain discovery
sfp_crt                  # Certificate Transparency logs

# Network
sfp_portscan_tcp         # TCP port scanning
sfp_portscan_basic       # Basic port scan
sfp_shodan               # Shodan search
sfp_censys               # Censys search
sfp_binaryedge           # BinaryEdge search
sfp_greynoise            # GreyNoise intelligence

# Web
sfp_spider               # Web spider/crawler
sfp_webanalytics         # Web analytics IDs
sfp_webframework         # Web framework detection
sfp_wappalyzer           # Technology detection

# Email
sfp_emailformat          # Email format discovery
sfp_hunter               # Hunter.io email lookup
sfp_emailcrawlr          # EmailCrawlr lookup
sfp_haveibeenpwned       # HIBP breach check

# Social Media
sfp_social_media         # Social media profiles
sfp_instagram            # Instagram lookup
sfp_twitter              # Twitter lookup
sfp_github               # GitHub repos and users

# Reputation & Threat Intel
sfp_abuseipdb            # AbuseIPDB reputation
sfp_virustotal           # VirusTotal lookup
sfp_threatminer          # ThreatMiner lookup
sfp_maltiverse           # Maltiverse threat intel
sfp_alientvault          # AlienVault OTX
sfp_ibmxforce            # IBM X-Force
sfp_urlhaus              # URLHaus malware URLs

# WHOIS & Registration
sfp_whois                # WHOIS lookup
sfp_builtwith            # BuiltWith technology
sfp_bgpview              # BGP/ASN info

# Data Leaks
sfp_haveibeenpwned       # HIBP breach check
sfp_dehashed             # Dehashed leak DB
sfp_leakix               # LeakIX exposure data
sfp_snov                 # Snov.io email intel

# Geolocation
sfp_geoip                # GeoIP lookup
sfp_ipinfo               # IPInfo lookup

API KEY CONFIGURATION#

# Settings > API Keys (Web UI)
# Or edit: ~/.spiderfoot/spiderfoot.conf

# Common API keys to configure:
  Shodan                  # Internet device search
  Censys                  # Host/cert search
  VirusTotal              # File/URL/domain analysis
  Hunter.io               # Email finder
  HaveIBeenPwned          # Breach data
  SecurityTrails          # DNS/domain intelligence
  BinaryEdge              # Internet scanning data
  FullContact             # People/company data
  Clearbit                # Company enrichment
  Builtwith               # Technology detection
  IPInfo                  # IP geolocation
  AbuseIPDB               # IP reputation
  AlienVault OTX          # Threat intelligence
  GitHub                  # Code/user search
  Dehashed                # Leaked credentials
  GreyNoise               # Internet scanner intel

RESULTS ANALYSIS#

# Data Browser
  - Browse all findings by data type
  - Filter by module or entity type
  - Export as CSV/JSON

# Graph View
  - Visual relationship graph
  - Shows connections between entities
  - Click nodes for details
  - Useful for identifying relationships

# Correlations
  - Cross-module correlation
  - Same data found by multiple sources = higher confidence
  - SpiderFoot links related entities automatically

# Data Types Found
  - IP addresses, subnets, ASNs
  - Domain names, subdomains
  - Email addresses, phone numbers
  - Usernames, person names
  - Web technologies, frameworks
  - Open ports, services
  - SSL certificates
  - Social media profiles
  - Data breaches, leaked credentials
  - Malware associations
  - Physical locations (GeoIP)

SPIDERFOOT HX (CLOUD)#

# Commercial hosted version: https://hx.spiderfoot.net
# Features:
  - Scheduled/recurring scans
  - Team collaboration
  - More data sources
  - Case management
  - No infrastructure to manage

AUTOMATION EXAMPLE#

#!/bin/bash
# Quick passive recon script
TARGETS="target1.com target2.com target3.com"

for target in $TARGETS; do
    python3 sfcli.py -s "$target" -t passive -o json > "${target}_recon.json"
    echo "Completed: $target"
done

TIPS#

  - Start with Passive scan to avoid alerting the target
  - Configure API keys for much richer results
  - Shodan + Censys + VirusTotal APIs are most impactful
  - Graph view reveals hidden relationships between entities
  - Use CLI for automation and scripting
  - Docker deployment is easiest for quick setup
  - Scan results persist in SQLite database
  - Re-run scans to track changes over time
  - Combine with manual OSINT for best results
  - Export to CSV for processing in other tools